Splunk Cloud Platform

how users are deprovisioned from Splunk Cloud

sc_admin11
Engager

Considering our current setup i.e authentication and Authorization integrated with SAML, how do we
1. mark an user inactive

2. what do we do with his/her knowledge objects.

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

I just checked a Splunk Cloud stack and the only users with the delete option are local.  The SAML users do not have the Edit action, therefore no delete.

---
If this reply helps you, Karma would be appreciated.

richgalloway
SplunkTrust
SplunkTrust

1. You can't.  Splunk doesn't know if a user is active or not - only that they pass authentication (or not).  A user never signing in is just a user who never signs in rather than an inactive/expired user.  You can, however, file a support request to have the user removed.

2. Assign the user's KOs to another user.  Go to Settings->All configurations and click the "Reassign Knowledge Objects" button.

---
If this reply helps you, Karma would be appreciated.

sc_admin11
Engager

If we delete user without reassign KO to other user. Than what would happen with that KOs.

@richgalloway 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The KOs will remain, but will become "orphans" (owned by nobody).  They can be re-assigned to another user, however.

---
If this reply helps you, Karma would be appreciated.
0 Karma

sc_admin11
Engager

Is there any search query from which we can get the inactive users? @richgalloway @_JP 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

This query will tell you when each user last logged in.  It's up to you to decide which of them is "inactive".

| rest /services/authentication/users splunk_server=local | table title last_successful_login
---
If this reply helps you, Karma would be appreciated.

sc_admin11
Engager

@richgalloway in table i got empty column for 

last_successful_login

 Screenshot 2023-10-26 at 12.11.48 PM.png

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...